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Description of Information 

Classification/Markings 

Reason 

Declass 

Remarks 

A. (U) GENERAL 





1. (U) The fact that NS A/CSS or 
TAO performs computer 
network exploitation (CNE) 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

2. (S//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, performs 
remote subversion 

SECRET//REL TO USA, 

FVEY 

Sec 1.4(c) 

*25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
and/or require 
compartmentation. 

(U) Foreign releasability 
decisions on specific details 
relating to remote subversion 
are handled on a case-by-case 
basis. Contact TAO CAO for 
further guidance. 

3. (S//SI//REL) Identification of 
specific remote subversion 
methods used by NSA/CSS or 
TAO, to include: 

- Endpoint access, exploitation, 
or operations 

- On-net access, exploitation, or 
operations 

- Software implant access, 
exploitation, or operations 

- Accessing or exploiting data 
at rest 

SECRET//SI//REL TO USA, 
FVEY 

Sec 1.4(c) 

*25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
and/or require 
compartmentation. 

(U) Foreign releasability 
decisions on specific details 
relating to remote subversion 
are handled on a case-by-case 
basis. Contact TAO CAO for 
further guidance. 

4. (S//SI//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, performs 
physical subversion, to include: 

SECRET//SI//REL TO USA, 
FVEY 

Sec 1.4(c) 

*25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification and 
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- Close access enabling, 
exploitation, or operations 

- Off-net enabling, exploitation, 
or operations 

- Supply chain enabling, 
exploitation, or intervention 
operations 

- Hardware implant enabling, 
exploitation, or operations 




require ECI protection. 

(U) Foreign rclcasability 
decisions on specific details 
relating to physical 
subversion are handled on a 
casc-by-casc basis. Contact 
TAG CAO for further 
guidance. 

5. (U) The association of any 

specific EC1 name or tngraph, 
with NS A/CSS, BC1, S1GINT, 
or intelligence 

UNCLASSIFIED FOR 
OFFICIAL USE GNLY 

FGIA3 

N/A 


6. (U) I*hc association of a 

specific TAG ECI name or 
tngraph with CNE and/or TAO 

CONFIDENTIAL'/REL TO 
USA, FVEY 

See. 1 .4(c) 

N/A 


7. (U) The fact that a specific 
individual is cleared for a 
specific TAO ECI, when there 
is no association between the 

ECI and TAG 

UNCLASSIFIED'FOR 
OFFICIAL L SB ONLY 



(U) If the details of the 
association reveal the fact 
that the ECI is TAG’s. then it 
would be 

C0NF1DENTIAL//REL IO 
USA, FVEY, in accordance 
with entry 5. 

8 . ( U) *I*hc fact that NSA/CSS or 
TAG conducts CNE for foreign 
intelligence collection. 

UNCLASSIFIED 

N/A 

N/A 


9. (U) The fact that NSA/CSS or 
TAG, as part of CNE 
operations, performs CNE to 
support U.S. Government CNA 
efforts 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

10. (U) The fact that NSA CSS or 
TAG, as part of CNE 
operations, trains, equips, and 
organizes the U.S. Cryptologic 
System to support the CNE, 
CNA. and CND requirements 
needs of its customers 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

11. (U) *I*hc fact that NSA/CSS or 
TAG, as part of CNE 
operations, provides CNO- 
rclated military targeting 
support 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

12. (U) The fact that NSA/CSS or 
TAG, as part of CNE 
operations, provides 
intelligence gam/loss 
assessments in response to 
Combatant Commander 
(CGCOM) CNO targeting 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

13. (U) The fact that NSA>CSS or 
TAG, as part of CNE 
operations, develops and 
supports analytic modeling and 
simulation techniques to 
support CNECNA efforts 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 
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14. (U) I*he fact that NSA/CSS or 
TAO, as part ofCNE 
operations, targets, collects and 
processes computers, computer 
networks and computcr-to- 
computcr (C2C) 
communications without 
reference to a specific 
operation, activity or target 

UNCLASSIFIED 

N/A 

N/A 

(U) Details indicating 
specific targets, level of 
success or capabilities remain 
classified. 

15. (S//S1//REL) Ilic fact that NSA 
or TAG, as part of CNH 
operations, targets, collects and 
processes specific computer 
protocols (such as email, instant 
messaging, file transfer 
protocols) 

SHCRHT//S1//REL TO USA, 
FVEY 

See 1.4(c) 

♦25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 

ECls and'or a different level 
of foreign rclcasability 
(including NOFORN). 

16. (S//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNH operations, remotely 
introduces code into target 
computer networks to facilitate 
foreign intelligence collection 

SECRET//SI//REL TO LSA. 
FVEY 

See 1.4(c) 

♦25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 

HCls and'or a different level 
of foreign rclcasability 
(including NOFORN). 

17. (TS//SL7REL) The fact that 
NSA/CSS or TAO, as part of 
CNH operations, conducts off- 
net field operations to develop, 
deploy, exploit, or maintain 
intrusive access, w ithout further 
detail 

TOP SECRET//SI//REL TO 
LSA. FVEY 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

HCls and'or a different level 
of foreign rclcasability 
(including NOFORN). 

18. (S//S1//REL) The fact that 
NSA/CSS or TAO, as part of 
CNH operations, conducts off- 
net activities at specified 
locations other than NSA/CSS 
facilities 

TOP SHCRHT//S1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by an HC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
by-casc basis. Contact TAO 
CAO for further guidance. 

19. (U) TAO project names, in 
association with CNH or TAO. 
with no amplifying details 

UNCLASS IFIEIV/FOR 
OFFICIAL USE ONLY 

FOIA (3) 

N/A 


B. (V) PARTNERIN' G/COLL ABO RATION 

20. (C//RHL) The fact that 

NSA/CSS or TAO, as part of 
CNH operations, collaborates 
with Second Party Partners to 
conduct CNH activities 

CONHDENTIAL'REL TO 
LSA. FVEY 

See 1.4(c.d) 

♦25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(U) Details may also be 
protected by one or more 
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ECls. 

21. (C//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with specific Second Party 
partners on specific ECls 

CONI 1DENT1AL7REL TO 
USA, FVEY 

See remarks tor foreign 
rclcasability. 



(U) Foreign rclcasability 
decisions handled on a ease- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

22. (C7/REL) Details of the CNE 
collaboration between 

NSA/CSS or TAO and Second 
Party partners 

SECRET/.'Sl at a minimum 

Sec remarks tor foreign 
rclcasability. 



(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET//SI. 

(U) Details may also be 
protected by one or more 

ECls. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

23. (S//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with unspecified Third Party 
Partners in support and conduct 
of CNE activities 

SECRET//REL TO USA, 

FVEY 

See 1.4(c.d) 

♦25 yean* 

(U) Details may also be 
protected by an EC1. Contact 
TAO CAO for further 
guidance. 

24. (S//REL) The fact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with specified Third Party 
Partners in support and conduct 
of CNE activities 

TOP SECRET//S1 

See remarks tor foreign 
rclcasability. 

See 1.4(c.d) 

♦25 years 

(U) Foreign rclcasability 
decisions handled on a casc- 
by-casc basis. Contact TAO 
CAO for further guidance. 

(U) Details may also be 
protected by an EC1. Contact 
TAO CAOVor further 
guidance. 

25. (U//FOUO) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with a specific US 
Govcmmcnt'lC entity 

UNCLASS IF1ED//FOR 
OFFICIAL l SB ONLY 

FOIA (3) 

N7A 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(U ) Details may also be 
protected by one or more 

ECls and'or a different level 
of foreign rclcasability 
(including NOFORN). 

26. (C7/REL) The tact that 

NSA/CSS or TAO, as part of 
CNE operations, collaborates 
with a specific US 
Govcmmcnt'lC entity on a 
specific EC1 

CONF1DENT1AL//REL TO 
USA, FVEY 

See. 1 .4(c) 

♦25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level. 

(IT) Details may also be 
protected by one or more 

ECls and'or a different level 
of foreign rclcasability 
(including NOFORN). 
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C. (U) TOOLS AND 1UC HMQLKS 


27. (U) The existence of CNE 
tools, with no further 
dctails/context 

UNCLASSIFIED 

N/A 

N/A 


28. (U) Cover names of CNE tools, 
with no dctails/contcxt 

UNCLASSIFIED 

N/A 

N/A 


29. (S//S1//RHL) When associated 
with remote subversion, 
details.* descriptions concerning 
CNE tools, to include: 

- Specific type (ie. 
hardware,'software, etc.) 

- Purpose 

- Capabilities 

- Concealment Techniques 

- Electronic signatures 

- Combination(s) of the above 

SECRET//S1 
at a minimum 

See remarks for foreign 
relcasability. 

See. 1 .4(c) 

♦25 years 

(IT) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 

ECls and'or a different level 
of foreign relcasability 
(including NOFORN). 

(U) Foreign relcasability 
decisions handled on a ease- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

30. (S//SI//REL) When associated 
with physical subversion, 
dctailsdescriptions concerning 
CNE tools, to include: 

- Specific t>pc (ir. 
hardware software, etc.) 

- Purposc- 

- Capabilities 

- Concealment Techniques 

- Electronic signatures 

- Combination s) of the 

above 

TOP SECRET,VS1 

See remarks for foreign 
relcasability 

See 1.4(c) 

♦25 years 

(U) Details indicating 
specific targets, level of 
success or capabilities may 
raise the classification level 
to TOP SECRET. 

(U) Details may also be 
protected by one or more 

ECls and'or a different level 
of foreign relcasability 
(including NOFORN). 

(U) Foreign relcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

31. (U//FOUO) Technical details 
concerning specific software 
vulnerabilities, when publicly 
know n, and that arc exploited 
for CNE activines 

UNCLASSIFIED,',TOR 
OFFICIAL l SE ONLY 

FOIA (3) 

N/A 


32. (S//S1//REL) Technical details 
concerning specific software 
vulnerabilities, when not 
publicly known, and that are 
exploited for CNE activities 

TOP SECRET,VS1 

See remarks for foreign 
relcasability. 

See 1.4(c) 

♦25 years 

(U) Details may be protected 
as NOFORN on a case-by- 
casc basis. 

(U) Some tools may be 
protected under an ECI 
and'or additional handling 
caveats. 

(U) Foreign relcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for f urther guidance. 
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| D. (U) OPERATIONS and TARGETING 


33. (U)Thc fact that NSA/CSS or 
TAO, as part ofCNE 
operations, targets a specific 
country or international 
organization 

SECRET/,SL/REL TO USA, 
FVEY at a minimum 

See. 1.4(c) 

♦25 years 

(U) Details may also be 
protected by a different level 
of foreign rclcasability 
(including NOFORN). 

(U) Contact TAO CAO for 
further guidance on levels of 
success as well as for more 
specific targeting details such 
as mdividual(s), specific 
government cntity(ies), etc. 

34. (S//S1//REL) Association of 
cover names tor ofi-nct 
operations lie., physical 
subversion activities) with 
amplifying details (c.g.. 
specific electronic components, 
systems, their host facilities, 
etc) 

TOP SECRET//S1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(IT) Details may also be 
protected by one or more 

ECU. 

(U) Foreign rclcasability 
decisions handled on a ease- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

35. (S//REL) Association of cover 
names for on-net operations 
(i.c.. remote subversion 
activities) with amplifying 
details (c.g., specific electronic 
components, systems, their host 
facilities, etc) 

SECRET/,SI at a minimum 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

ECU. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

36. (S//S1//REL) Individual details 
of CNE activities, such as: 

- Target information including 
intended target network and'or 
device 

- Vulnerability being targeted 

- Target infrastructure 

TOP SECRET,VS1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

ECU. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO tor further guidance. 

37. (TS//SI//REL) The fact that 
NSA/CSS or TAO, as part of 
CNE operations, is attempting 
to exploit or has succeeded in 
exploiting a specific 
vulnerability (c.g., in a firewall, 
operating system, software 
application, etc.), and a specific 
entity or facility within a 
target’s nVcomputer structure 

TOP SECRET7S1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

EC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

38. (S//S1//RHL) Facts related to 
the description of U.S. 
hardware or software implants 
and location (c.g.. specific 
organization and Internet 

Protocol DcviccvAddress, etc.) 
on a target's 

IT'communications system 

TOP SECRET/VSl 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

EC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

39. (S//SI//REL) Facts related to 
the exact timing, location. 

TOP SECRET,','SI 
at a minimum. 

See 1.4(c) 

♦25 years 

• l i Ddlih may also be 
protected by one or more 
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participants, off-net or on-net 
operations, CNE command, 
control and data exfiltration 
tools capabilitics and locations, 
used to exploit or maintain 
intrusive access to a target's 
nVeomputer structure 

See remarks for foreign 
rclcasability. 



EC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAO 
CAO for further guidance. 

40. (S//S1//REL) Combination of 
details of individual aspects of 
CNE activities, that would 
allow a specific target to take 
specific counter-measures, such 
as: 

- Specific target network or 
device and 

- Specific capability, tool or 
technique used for exploitation 
of vulnerability 

TOP SECRET,VS1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

♦25 years 

(U) Details may also be 
protected by one or more 

EC1. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAG 
CAO for further guidance. 

41 . (TS//SL7REL) The fact that 
NSA/CSS (or TAG) acquires 
cryptographic enabling 
information through CNE 
activities. 

TOP SECRET//S1 

See remarks for foreign 
rclcasability. 

See 1.4(c) 

4 25 years 

(U//FOUO) Details may also 
be protected by one or more 
EC1 andor HCS. 

(U) Foreign rclcasability 
decisions handled on a casc- 
bv-casc basis. Contact TAG 
CAO for further guidance. 


(U) *25 years: Declassification in 25 years indicates that the information is classified tor 25 years from the date a 
document is created or 25 years from the date of this original classification decision, whichever is later. 

AC RON V MS/DEF1N 1T1GNS: 


(U) Computer Network exploitation (CNE): intelligence collection and enabling operations to gather data from 
target or adversary automated information systems (AIS) or networks. (Per DCID 7/3, Information Operations and 
Intelligence Community Related Activities, effective 01 July 1999, administratively changed 5 June 2003) 

(U) Computer Network Attack (CNA): operations to manipulate, disrupt, deny, degrade, or destroy information 
resident in computers and computer networks, or the computers and networks themselves. (Per DCID 7/3. Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 

(U) Computer Network Defense (CND): efforts to defend against the CNO of others, especially that directed against 
U.S. and allied computers and networks. (Per DCID 7/3, Information Operations and Intelligence Community Related 
Activities, effective 01 July 1999, administratively changed 5 June 2003) 

(U) Computer Network Operations (CNO): CNE, CNA, and CND collectively. (Per DCID 7/3, Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 

(U) Information Operations (IO): actions taken to affect adversary information and information systems while 
defending one's own information and information systems. IO is an integrating strategy. (Per DCID 7/3, Information 
Operations and Intelligence Community Related Activities, effective 01 July 1999. administratively changed 5 June 
2003) 
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(S//SLVRHL) Intrusive Access: Refers to CNE operations involving remote manipulation, hardware/software 
modifications, or sensing of environment changes in a computer device or system, and/or occasionally the facilities that 
house the systems. 

(S//SI//REL) Off-Net Operations: Refers to covert or clandestine field activities of personnel carried out in support of 
CNE activities. 

(S//SI//REL) Physical subversion: Subverts with physical access to a device or host facility. Other terms sometimes 
used to connote physical subversion arc close access enabling, exploitation, or operations: off-net enabling, 
exploitation, or operations; supply-chain enabling, exploitation, or operations: or hardware implant enabling, 
exploitation, or operations. 

(&//SI//REL) Remote subversion: Subverts without physical access to a device or host facility; obtains unauthorized 
permission. Other terms sometimes used to connote remote subversion are computer network exploitation; endpoint 
access, exploitation, or operations; on-net access, exploitation, or operations, software implant access, exploitation, or 
operations; or accessing or exploiting data at rest. 

(S//SI//REL) Supply Chain Operations: Interdiction activities that focus on modifying equipment in a target’s supply 
chain. 
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